Article 93 of Regulation (EU) 2024/1689 — Power to request measures. Official text, practical interpretation, key obligations and compliance implications.

Official Text Summary

Article 93 of Regulation (EU) 2024/1689 (the EU AI Act) sits in Chapter IX, Section 5 — the section that gives the Commission, acting through the AI Office, exclusive supervisory powers over providers of general-purpose AI (GPAI) models. Within that section it is the third and most consequential rung of an escalating enforcement ladder: Article 91 lets the Commission request documentation and information, Article 92 lets it conduct evaluations of a model, and Article 93 lets it demand that the provider actually do something about what those steps reveal. Unlike the market-surveillance powers elsewhere in Chapter IX, these powers are not exercised by national authorities: for GPAI models, the Commission is the single enforcer across the Union.

Article 93(1) authorises the Commission, where necessary and appropriate, to request a provider to do one of three things: (a) take appropriate measures to comply with the provider obligations set out in Articles 53 and 54; (b) implement mitigation measures, where an evaluation carried out under Article 92 has given rise to serious and substantiated concern of a systemic risk at Union level; or (c) restrict the making available on the market of the model, or withdraw or recall it. The three limbs form their own internal escalation, from ordinary compliance through targeted mitigation to removal of the model from the Union market.

The two remaining paragraphs build in de-escalation. Under Article 93(2), before any measure is requested, the AI Office may open a structured dialogue with the provider. Under Article 93(3), if a provider of a GPAI model with systemic risk offers commitments to implement mitigation measures, the Commission may by decision make those commitments binding on the provider and declare that there are no further grounds for action — closing the procedure without a formal measure ever being imposed.

What This Means in Practice

Formally, limb (a) reaches any GPAI model provider that falls short of its Article 53 obligations (technical documentation, information to downstream providers, copyright policy, training-content summary) or Article 54 (authorised representative for non-EU providers). In practice, the centre of gravity is the small group of providers whose models are classified as carrying systemic risk under Articles 51 and 52 — the presumption threshold being training compute above 10²⁵ FLOPs — because the mitigation and recall limbs are tied to systemic-risk findings from Article 92 evaluations.

For those providers, Article 93 is where supervision acquires teeth. A documentation request is an administrative burden; an evaluation is scrutiny; a request for measures is an order with a fining mechanism behind it. Refusal exposes the provider to fines under Article 101 of up to 3% of worldwide annual turnover or €15 million, whichever is higher — and non-compliance with the request is a fining ground of its own, independent of the underlying breach.

The limb with the widest blast radius is (c). A restriction, withdrawal or recall of a frontier model is existential for its provider, but it does not stop there: every downstream AI system built on that model inherits the disruption. An organisation that has integrated a systemic-risk model into its products has, in effect, a regulatory dependency it does not control. Prudent downstream providers and deployers therefore track the regulatory standing of their upstream model and address the recall scenario contractually — continuity commitments, migration assistance, notification duties.

The commitments mechanism in Article 93(3) will do much of the real work. It mirrors the commitments decisions of EU competition law: the provider offers a package of mitigations, the Commission makes it binding, and both sides avoid a contested measure. A worked example: an Article 92 evaluation of a frontier model raises serious and substantiated concern that its capabilities could meaningfully assist the creation of biological threats. The AI Office opens a structured dialogue; the provider offers staged access controls, enhanced refusal training and third-party red-teaming on a defined timetable; the Commission makes those commitments binding and closes the file. No recall, but an enforceable safety upgrade.

Key Obligations

Relationship to Other Articles

Article 93 completes the enforcement chain of Chapter IX, Section 5. Article 88 establishes the Commission's exclusive enforcement competence for GPAI providers; Article 89 provides monitoring; Article 90 channels alerts of systemic risk from the scientific panel — often the trigger for everything that follows. Article 91 (documentation and information) and Article 92 (evaluations) are the investigative rungs immediately below Article 93, and an Article 92 finding of serious and substantiated concern is the express precondition for a mitigation request under 93(1)(b). Article 94 guarantees the procedural rights of the economic operators concerned.

The substantive obligations that a request enforces live in Articles 53 and 54 (all GPAI providers) and Article 55 (providers of models with systemic risk), with classification and designation governed by Articles 51 and 52. Adherence to a code of practice under Article 56 is the practical way a provider demonstrates compliance — and therefore the cheapest insurance against ever receiving a request. The fining backstop is Article 101. For the wider context of GPAI regulation, see the GPAI hub; for penalty exposure across the Act, see Article 99.

Compliance Timeline

The Regulation entered into force on 1 August 2024. The substantive GPAI obligations that Article 93 enforces — Articles 53 to 55 — have applied since 2 August 2025. The Commission's enforcement powers under Chapter IX, Section 5, including the power to request measures, apply from 2 August 2026, together with the Article 101 fining power over GPAI providers.

The 2026 Digital Omnibus did not touch this track: it deferred the high-risk obligations of Annex III and Annex I to 2 December 2027 and 2 August 2028 respectively, but left the GPAI framework and its enforcement dates intact. For providers of systemic-risk models, the practical preparation is straightforward to state and demanding to do: keep Articles 53–55 evidence current, adhere to a code of practice, rehearse the structured-dialogue scenario, and have a commitments strategy ready before the AI Office ever calls.

Official AI Act Compliance Deadline Calendar

Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.

Obligation Applies to Original date New date Status Countdown Legal basis
Prohibited Practices (Art. 5) All providers and deployers active AI Act Art. 5
GPAI Rules (Chapter 5) GPAI model providers active AI Act Art. 51-56
Commission Enforcement Powers over GPAI GPAI model providers active AI Act Art. 88-94, 101
Transparency Obligations (Art. 50) Providers and deployers of chatbots, generative, emotion recognition systems active AI Act Art. 50
New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) Providers and deployers of generative AI systems active AI Omnibus 2026 Art. 5
AI-Generated Content Marking (pre-existing systems) Providers of generative AI systems on the market before 2 Aug 2026 active AI Act Art. 50(2) — transitional
Regulatory Sandboxes National competent authorities deferred AI Omnibus 2026 Art. 57
High-risk AI — Annex III (standalone) Providers of standalone Annex III systems deferred AI Omnibus 2026 Art. 6(2)
High-risk AI — Annex I (embedded) AI embedded in Annex I regulated products deferred AI Omnibus 2026 Art. 6(1)

Download JSON · CC BY 4.0

Frequently Asked Questions

Three things, in escalating order of severity: that a provider of a general-purpose AI model take measures to comply with its obligations under Articles 53 and 54; that it implement mitigation measures where an Article 92 evaluation has raised serious and substantiated concern of a systemic risk at Union level; or that it restrict the making available on the market, withdraw, or recall the model.

Directly, providers of general-purpose AI models — in practice above all providers of models with systemic risk, since the mitigation and recall powers are tied to systemic-risk findings. Indirectly, every downstream provider and deployer whose AI systems are built on such a model: a restriction or recall of the upstream model cascades through every system that depends on it.

The Commission can impose fines under Article 101 of up to 3% of worldwide annual turnover or €15 million, whichever is higher. Non-compliance with a request for measures is itself a fining ground, separate from the underlying breach. The market-restriction, withdrawal and recall option in Article 93(1)(c) remains available as the ultimate enforcement step.

Yes. Under Article 93(3), if the provider offers commitments to implement mitigation measures addressing the systemic risk, the Commission may by decision make those commitments binding and declare that there are no further grounds for action — a settlement mechanism familiar from EU competition law.

Stay ahead of AI Act changes

Get compliance alerts when deadlines or obligations change.

No spam. One-click unsubscribe.

Take compliance further with the AI Act Academy

Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.